Restrict Apps a User can View when Configuring Okta AWS CLI for Multiple AWS Environments
Last Updated:
Overview
The okta-aws-cli utility can be configured so a single OIDC Application can work with multiple AWS Federation Applications. When configuring the CLI for multiple AWS Applications users assigned to the application require Admin Read Rights for Applications in Okta.
This can provide unwanted read access to apps for these users.
Applies To
- Okta Identity Engine
- okta-aws-cli
- Okta AWS Federation Application (SAML)
Cause
In order for the CLI to retrieve the AWS Federation application instances in an Okta Org, users need to be part of an Admin group with enough permissions to satisfy the Okta scope 'okta.apps.read'. Builtin Okta Admin groups will give users access to all applications, not just the AWS Federation Applications.
Solution
Create a Role:
- Select the 'roles' tab and click 'create new role'
- Provide a name and description
- For 'View by type' select 'Application' only
- Under 'Application permissions' select 'View application and their details', then save
- Select the 'Resources' tab and click 'Create new resource set'
- Provide a name and description
- Click 'Add Resource'
- Type 'Applications' and select it
- Click 'Select Applications'
- Type 'AWS', then select 'All AWS Account Federation Apps'
- Click Create
- Select the 'Admins' tab and click 'Add Administrator'
- Under 'Select Admin' type a username or group to add
- Under 'role' select the role created
- Under 'Resource Set' select the resource set created
- Save
